Users plugin for Difra framework
38%
Total Score
unhealthy
Risky to depend on: no release or commit activity since February 2022.
The latest release was published in February 2022, and there have been no releases in roughly four years and seven months. Five total releases show some history, but the prolonged pause raises abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. The repository is not archived, but there is no observed recent maintenance.
A changelog is present in both the package and repository, but the package has no README and no tests. The changelog improves release transparency, while the missing README is a smaller consumer-documentation gap.
Composer is used as the build tool, but no security scanning tools were detected. The absence of scanning is a hygiene gap, though it is less decisive than the observed maintenance inactivity.
The repository has no security policy. For a user-management plugin handling authentication and account recovery, this weakens the project's vulnerability-reporting and response transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
difra/difra Version ~8.0.0 | — | — |
difra/capcha Version ~8.0.0 | — | — |
difra/lib-wordforms Version ~1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.